Versioning & deprecation
One contract version - currently v1.25.0 - reported identically by the OpenAPI spec, the MCP server’s serverInfo, and the MCP server card. It follows SemVer: major means a response-envelope break (a stable field removed, renamed, or changed in meaning, or the default response format flipping); minor means anything additive plus check-catalog membership changes, always with a changelog entry; patch means spec-only corrections. Pinning the major version is safe and recommended.
Stable fields are frozen within a major: domain, score, scoreMax, grade, layer and check ids, check status, score and maxScore, bonus, analysisStatus, pendingChecks, url, generatedAt, source, and the topFixes array’s presence and entry shape. An id never changes meaning while it exists, though catalog membership (which check ids run) may change on a minor release. Advisory fields (estScoreGain, tier, maturity, recommendation, details, naReason, gradeColor, name, specUrl, and topFixes ordering) may change on any release. Experimental fields (competitors) carry no guarantee.